Codex ships its own RG version which triggers MacOS safety standards

Resolved 💬 7 comments Opened Jul 10, 2026 by smileBeda Closed Jul 12, 2026

What version of Codex CLI is running?

0.144.1

What subscription do you have?

PRO and PLUS

Which model were you using?

sol

What platform is your computer?

Darwin 25.5.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

Ghostty

Codex doctor report

{
  "schemaVersion": 1,
  "generatedAt": "1783692029s since unix epoch",
  "overallStatus": "ok",
  "codexVersion": "0.144.1",
  "checks": {
    "app_server.status": {
      "id": "app_server.status",
      "category": "app-server",
      "status": "ok",
      "summary": "background server is not running",
      "details": {
        "control socket": "/Users/bedas/.codex/app-server-control/app-server-control.sock",
        "daemon state dir": "/Users/bedas/.codex/app-server-daemon",
        "mode": "ephemeral",
        "pid file": "/Users/bedas/.codex/app-server-daemon/app-server.pid (missing)",
        "settings": "/Users/bedas/.codex/app-server-daemon/settings.json (missing)",
        "status": "not running",
        "update-loop pid file": "/Users/bedas/.codex/app-server-daemon/app-server-updater.pid (missing)"
      },
      "remediation": null,
      "durationMs": 0
    },
    "auth.credentials": {
      "id": "auth.credentials",
      "category": "auth",
      "status": "ok",
      "summary": "auth is configured",
      "details": {
        "auth file": "/Users/bedas/.codex/auth.json",
        "auth storage mode": "Keyring",
        "stored API key": "false",
        "stored ChatGPT tokens": "true",
        "stored agent identity": "false",
        "stored auth mode": "chatgpt"
      },
      "remediation": null,
      "durationMs": 3
    },
    "config.load": {
      "id": "config.load",
      "category": "config",
      "status": "ok",
      "summary": "config loaded",
      "details": {
        "CODEX_HOME": "/Users/bedas/.codex",
        "config.toml": "/Users/bedas/.codex/config.toml",
        "config.toml parse": "ok",
        "cwd": "/Users/bedas/Developer/source/git/nautilus/praxis",
        "enabled feature flags": "shell_tool, unified_exec, shell_snapshot, code_mode_host, terminal_resize_reflow, sqlite, hooks, enable_request_compression, apps, tool_search_always_defer_mcp_tools, tool_suggest, plugins, in_app_browser, browser_use, browser_use_full_cdp_access, browser_use_external, computer_use, remote_plugin, plugin_sharing, image_generation, resize_all_images, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, auth_elicitation, personality, tui_app_server, prevent_idle_sleep, remote_compaction_v2, workspace_dependencies",
        "feature flag overrides": "multi_agent=false, fast_mode=false, prevent_idle_sleep=true",
        "feature flags enabled": "34",
        "log dir": "/Users/bedas/.codex/log",
        "mcp servers": "3",
        "model": "gpt-5.6-sol",
        "model provider": "openai",
        "sqlite home": "/Users/bedas/.codex"
      },
      "remediation": null,
      "durationMs": 0
    },
    "git.environment": {
      "id": "git.environment",
      "category": "git",
      "status": "ok",
      "summary": "git version 2.50.1 (Apple Git-155)",
      "details": {
        ".git entry": "directory",
        "PATH git #1": "/usr/bin/git",
        "PATH git entries": "1",
        "git branch": "main",
        "git build options": "git version 2.50.1 (Apple Git-155); cpu: arm64; no commit associated with this build; sizeof-long: 8; sizeof-size_t: 8; shell-path: /bin/sh; feature: fsmonitor--daemon; libcurl: 8.7.1; zlib: 1.2.12; SHA-1: SHA1_DC; SHA-256: SHA256_BLK",
        "git exec path": "/Applications/Xcode.app/Contents/Developer/usr/libexec/git-core",
        "git version": "git version 2.50.1 (Apple Git-155)",
        "repo detected": "true",
        "repo root": "/Users/bedas/Developer/source/git/nautilus/praxis",
        "selected git": "/usr/bin/git"
      },
      "remediation": null,
      "durationMs": 130
    },
    "installation": {
      "id": "installation",
      "category": "install",
      "status": "ok",
      "summary": "installation looks consistent",
      "details": {
        "PATH codex #1": "/opt/homebrew/bin/codex",
        "current executable": "/opt/homebrew/bin/codex",
        "install context": "brew (package /opt/homebrew/Caskroom/codex/0.144.1, bin /opt/homebrew/Caskroom/codex/0.144.1/bin, resources /opt/homebrew/Caskroom/codex/0.144.1/codex-resources, path /opt/homebrew/Caskroom/codex/0.144.1/codex-path)",
        "managed by bun": "false",
        "managed by npm": "false",
        "managed by pnpm": "false",
        "managed package root": "not set"
      },
      "remediation": null,
      "durationMs": 3
    },
    "mcp.config": {
      "id": "mcp.config",
      "category": "mcp",
      "status": "ok",
      "summary": "MCP configuration is locally consistent",
      "details": {
        "configured servers": "3",
        "disabled servers": "0",
        "stdio servers": "1",
        "streamable_http servers": "2"
      },
      "remediation": null,
      "durationMs": 4906
    },
    "network.env": {
      "id": "network.env",
      "category": "network",
      "status": "ok",
      "summary": "network-related environment looks readable",
      "details": {
        "proxy env vars": "none"
      },
      "remediation": null,
      "durationMs": 0
    },
    "network.provider_reachability": {
      "id": "network.provider_reachability",
      "category": "reachability",
      "status": "ok",
      "summary": "active provider endpoints are reachable over HTTP",
      "details": {
        "ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 404)",
        "reachability mode": "ChatGPT auth"
      },
      "remediation": null,
      "durationMs": 353
    },
    "network.websocket_reachability": {
      "id": "network.websocket_reachability",
      "category": "websocket",
      "status": "ok",
      "summary": "Responses WebSocket handshake succeeded",
      "details": {
        "DNS": "2 IPv4, 2 IPv6, first IPv6",
        "auth mode": "chatgpt",
        "connect timeout": "15000 ms",
        "endpoint": "wss://chatgpt.com/backend-api/<redacted>",
        "handshake result": "HTTP 101 Switching Protocols",
        "model provider": "openai",
        "models etag present": "true",
        "provider name": "OpenAI",
        "proxy env vars": "none",
        "reasoning header": "false",
        "server model present": "false",
        "supports websockets": "true",
        "wire API": "responses"
      },
      "remediation": null,
      "durationMs": 838
    },
    "runtime.provenance": {
      "id": "runtime.provenance",
      "category": "runtime",
      "status": "ok",
      "summary": "running brew on macos-aarch64",
      "details": {
        "commit": "unknown",
        "current executable": "/opt/homebrew/bin/codex",
        "install method": "brew (package /opt/homebrew/Caskroom/codex/0.144.1, bin /opt/homebrew/Caskroom/codex/0.144.1/bin, resources /opt/homebrew/Caskroom/codex/0.144.1/codex-resources, path /opt/homebrew/Caskroom/codex/0.144.1/codex-path)",
        "platform": "macos-aarch64",
        "version": "0.144.1"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.search": {
      "id": "runtime.search",
      "category": "search",
      "status": "ok",
      "summary": "search is OK (bundled)",
      "details": {
        "search command": "/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg",
        "search command readiness": "file exists",
        "search provider": "bundled"
      },
      "remediation": null,
      "durationMs": 0
    },
    "sandbox.helpers": {
      "id": "sandbox.helpers",
      "category": "sandbox",
      "status": "ok",
      "summary": "sandbox configuration is readable",
      "details": {
        "approval policy": "OnRequest",
        "codex-linux-sandbox helper": "none",
        "execve wrapper helper": "/Users/bedas/.codex/tmp/arg0/codex-arg0YpJR1E/codex-execve-wrapper",
        "filesystem sandbox": "restricted",
        "network sandbox": "restricted"
      },
      "remediation": null,
      "durationMs": 0
    },
    "state.paths": {
      "id": "state.paths",
      "category": "state",
      "status": "ok",
      "summary": "state paths and databases are inspectable",
      "details": {
        "CODEX_HOME": "/Users/bedas/.codex (dir)",
        "active rollout files": "1708 files, 1559307974 total bytes, 912943 average bytes",
        "archived rollout files": "0 files, 0 total bytes, 0 average bytes",
        "goals DB": "/Users/bedas/.codex/goals_1.sqlite (file)",
        "goals DB integrity": "ok",
        "log DB": "/Users/bedas/.codex/logs_2.sqlite (file)",
        "log DB integrity": "ok",
        "log dir": "/Users/bedas/.codex/log (dir)",
        "memories DB": "/Users/bedas/.codex/memories_1.sqlite (file)",
        "memories DB integrity": "ok",
        "sqlite home": "/Users/bedas/.codex (dir)",
        "state DB": "/Users/bedas/.codex/state_5.sqlite (file)",
        "state DB integrity": "ok"
      },
      "remediation": null,
      "durationMs": 632
    },
    "state.rollout_db_parity": {
      "id": "state.rollout_db_parity",
      "category": "threads",
      "status": "ok",
      "summary": "rollout files and state DB thread inventory agree",
      "details": {
        "default model provider": "openai",
        "rollout DB active files": "1708",
        "rollout DB active rows": "1708",
        "rollout DB archive mismatches": "0",
        "rollout DB archived files": "0",
        "rollout DB archived rows": "0",
        "rollout DB duplicate DB paths": "0",
        "rollout DB duplicate rollout thread ids": "0",
        "rollout DB malformed file names": "0",
        "rollout DB missing active rows": "0",
        "rollout DB missing archived rows": "0",
        "rollout DB model providers": "openai=1708",
        "rollout DB rows": "1708",
        "rollout DB scan cap reached": "false",
        "rollout DB scan errors": "0",
        "rollout DB sources": "vscode=708, subagent:other=525, cli=280, subagent:review=104, exec=42, mcp=39, subagent:thread_spawn=10",
        "rollout DB stale rows": "0"
      },
      "remediation": null,
      "durationMs": 6722
    },
    "system.environment": {
      "id": "system.environment",
      "category": "system",
      "status": "ok",
      "summary": "OS language en-US",
      "details": {
        "EDITOR": "set",
        "LANG": "en_US.UTF-8",
        "VISUAL": "set",
        "os": "Mac OS 26.5.1 [64-bit]",
        "os language": "en-US",
        "os type": "Mac OS",
        "os version": "26.5.1"
      },
      "remediation": null,
      "durationMs": 2
    },
    "terminal.env": {
      "id": "terminal.env",
      "category": "terminal",
      "status": "ok",
      "summary": "terminal metadata was detected",
      "details": {
        "COLORTERM": "truecolor",
        "TERM": "xterm-ghostty",
        "TERMINFO": "/Applications/Ghostty.app/Contents/Resources/terminfo (dir)",
        "TERM_PROGRAM": "ghostty",
        "color output": "enabled",
        "effective locale": "en_US.UTF-8",
        "multiplexer": "tmux 3.7b",
        "stderr is terminal": "true",
        "stdin is terminal": "true",
        "stdout is terminal": "true",
        "terminal": "Ghostty",
        "terminal size": "119x58",
        "terminal version": "1.3.1",
        "tmux allow-passthrough": "off",
        "tmux client termname": "xterm-ghostty",
        "tmux client termtype": "ghostty 1.3.1",
        "tmux extended-keys": "always",
        "tmux focus-events": "on",
        "tmux set-clipboard": "on",
        "tmux xterm-keys": "on"
      },
      "remediation": null,
      "durationMs": 40
    },
    "terminal.title": {
      "id": "terminal.title",
      "category": "title",
      "status": "ok",
      "summary": "terminal title configured",
      "details": {
        "terminal title activity": "true",
        "terminal title items": "activity, run-state, model, task-progress",
        "terminal title source": "configured"
      },
      "remediation": null,
      "durationMs": 0
    },
    "updates.status": {
      "id": "updates.status",
      "category": "updates",
      "status": "ok",
      "summary": "update configuration is locally consistent",
      "details": {
        "cached latest version": "0.143.0",
        "check for update on startup": "true",
        "last checked at": "2026-07-09T17:47:45.793260Z",
        "latest version": "0.144.1",
        "latest version status": "current version is not older",
        "update action": "brew upgrade --cask codex",
        "version cache": "/Users/bedas/.codex/version.json"
      },
      "remediation": null,
      "durationMs": 681
    }
  }
}

What issue are you seeing?

Codex ships its own RG version:

Ran command -V rg
  └ rg is /opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg

This immediately triggers mac's safety net and pops up a modal telling you RG is unverifiable and thus has to be deleted.

It should, instead, use the OS's RG and tell users to install it or whatever if you really insist having it, or at least fall back to that when installed

command -V rg
rg is /opt/homebrew/bin/rg

The current situation is unbearable and will trigger a warning on each and every codex interaction that even remotely reads something from disk.

What steps can reproduce the bug?

Open codex CLI, have it do some work and see the failure as soon it tries to run rg

What is the expected behavior?

A cli should not bundle independently available tools - instead if anything it should install them as a dependency and not bundle an unverifiable package

Additional information

Codex 0.144.1 is placing an ad-hoc-signed, quarantined, Gatekeeper-rejected executable ahead of the working /opt/homebrew/bin/rg.

xattr -l "$RG"
com.apple.provenance:
com.apple.quarantine: 0381;6a50e9a1;;F87AE0CE-FD19-4389-9A63-7E0846E16A6F
bedas@apollo praxis % codesign -dv --verbose=4 "$RG" 2>&1
Executable=/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg
Identifier=rg
Format=Mach-O thin (arm64)
CodeDirectory v=20400 size=31483 flags=0x20002(adhoc,linker-signed) hashes=981+0 location=embedded
VersionPlatform=1
VersionMin=720896
VersionSDK=984320
Hash type=sha256 size=32
CandidateCDHash sha256=a7dbf01facbbddf9e0356a5cefb5af62452a2c78
CandidateCDHashFull sha256=a7dbf01facbbddf9e0356a5cefb5af62452a2c782365f05fc472e748cad3ef63
Hash choices=sha256
CMSDigest=a7dbf01facbbddf9e0356a5cefb5af62452a2c782365f05fc472e748cad3ef63
CMSDigestType=2
Executable Segment base=0
Executable Segment limit=3751936
Executable Segment flags=0x1
Page size=4096
CDHash=a7dbf01facbbddf9e0356a5cefb5af62452a2c78
Signature=adhoc
Info.plist=not bound
TeamIdentifier=not set
Sealed Resources=none
Internal requirements=none
bedas@apollo praxis % spctl --assess --type execute --verbose=4 "$RG"
/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg: rejected

This does not prove malware, but it is unquestionably broken distribution and poor security UX. Mac users should not have to waive Gatekeeper for a hidden helper binary.

View original on GitHub ↗

7 Comments

smileBeda · 10 days ago

Temporary easiest solution, put this in your local agents.md or as part of prompt or whatever you like to instruct the llm:

only ever use `/opt/homebrew/bin/rg` when you need to use `rg`. Never ever attempt to use your own bundled version of `rg`.

This has a slight token overhead but is minimal and lets you use the tool adequately.

Aternus · 10 days ago

Confirmed independently on macOS 26.4.1 (25E253), arm64, with Codex CLI 0.144.1 installed via Homebrew Cask.

The bundled helper resolved first on PATH:

/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg

It had the same ad-hoc signature/CDHash reported above (a7dbf01facbbddf9e0356a5cefb5af62452a2c78), carried com.apple.quarantine, and was rejected by spctl. The separately installed /opt/homebrew/bin/rg 15.1.0 worked normally.

One additional packaging datapoint: quarantine was not limited to rg; it was present across the versioned Caskroom tree and on all four shipped executables:

  • bin/codex
  • bin/codex-code-mode-host
  • codex-path/rg
  • codex-resources/zsh/bin/zsh

codex and codex-code-mode-host had valid Developer ID signatures from OpenAI (TeamIdentifier=2DC432GLL2). The bundled rg and zsh were only ad-hoc signed. codesign --verify passed for all four, so this looked like quarantine/Gatekeeper distribution behavior rather than file corruption.

Removing com.apple.quarantine from each executable resolved the prompts. Afterward, codex --version, codex --help, codex exec --help, codex-code-mode-host --help, the bundled zsh, and bundled rg --version all completed successfully. Homebrew reported no missing dependencies or partial installation.

This suggests the release/cask fix should cover every executable helper in the packaged tree, not only rg; otherwise another bundled helper may trigger the same behavior later.

smileBeda · 10 days ago
This suggests the release/cask fix should cover every executable helper in the packaged tree, not only rg; otherwise another bundled helper may trigger the same behavior later.

I disagree. The release should not bundle things that should be installed as dependencies. Literally this is what package managers are for. Codex can request zsh, rg, or whatever else it pleases to be installed through brew. This is how other tools do it (say, if you install openssl it will pull some other stuff too, not bundle it)

Similarly, in a python app you are not bundling python libs, you write a requirements.txt that pip installs for it on venv, for example.

PS: I might misunderstand what you mean, it sounds like you suggest they should keep shipping it bundled, but signed.

---

That said, thanks for adding those other details, I could not find but feared there might be more.

abtris · 10 days ago

I can reproduce this on macOS with Codex CLI 0.144.1 installed via Homebrew Cask.

macOS shows a Gatekeeper dialog:

“rg” Not Opened — Apple could not verify “rg” is free of malware that may harm your Mac or compromise your privacy.

The bundled Codex rg is selected ahead of the normal Homebrew ripgrep:

$ command -v rg
/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg

$ type -a rg
rg is /opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg
rg is /opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg
rg is /opt/homebrew/bin/rg

$ rg --version
# no output; process killed with exit code 137

The separately installed Homebrew ripgrep at /opt/homebrew/bin/rg is present, but Codex prepends its bundled codex-path/rg, which macOS blocks. This makes searches fail until the bundled binary's quarantine/signing issue is worked around.

darthShadow · 10 days ago

Duplicate of https://github.com/openai/codex/issues/28190.

This is fixed upstream again by reverting back to the standalone binary. You will need to update brew (so it knows about the latest hashes) & then do a reinstall to get it fixed.
goyiii44545-gif · 8 days ago

I recomend that you update to the latest version of codex

https://learn.chatgpt.com/docs/codex/cli#getting-started

<img width="1128" height="774" alt="Image" src="https://github.com/user-attachments/assets/639819bc-ec15-4b59-b20c-1ddfb081402c" />

smileBeda · 8 days ago

The commands now resolve to host-installed packages, not Codex-bundled copies:

  • rg → /opt/homebrew/bin/rg
  • Symlink to /opt/homebrew/Cellar/ripgrep/15.1.0/bin/rg
  • Installed and managed by Homebrew
  • Version: ripgrep 15.1.0
  • zsh → /bin/zsh
  • Apple’s host OS binary
  • Code-signing identifier: com.apple.zsh
  • Version: zsh 5.9
  • Universal macOS executable

The issue seems resolved - probably until the next release only tho.